2. What personal data we collect
We collect only what's needed to run the Service. Here's the complete list, organized by when we collect it.
2.1 When you sign up
- Email address — for magic-link authentication. We do not collect passwords; authentication is passwordless.
- Age attestation — a record that you confirmed you are 13 years of age or older at account creation. We do not collect your actual date of birth.
- Policy acceptance — a timestamp and version reference indicating which version of this Privacy Policy and our Terms of Service you accepted at account creation.
2.2 When you use the Service
- Content you create or upload — classes, decks, flashcards (including text and images for Hide & Reveal cards), notes, uploaded study materials (PDF, PPTX, DOCX). This content is private to you by default.
- Study activity — which cards you reviewed, when, your rating (again / hard / good / easy), session duration, and related metadata used for spaced-repetition scheduling.
- Timing telemetry — per-card response time used to improve scheduling estimates. Sampled and capped to limit heavy-tail outliers.
- Scheduling + calibration state — derived from your study activity; used to compute when cards are next due.
2.3 Automatically, when you interact with the Service
- Log data — IP address, browser user-agent, request path, HTTP status, and response time. Collected by our hosting provider (Vercel) and database provider (Supabase) for operational and security purposes. Scrubbed of sensitive fields before being sent to our error monitoring provider (Sentry).
- Session cookies — a Supabase auth cookie that keeps you signed in. No other cookies are set.
- Error reports — when something goes wrong, we capture the error context via Sentry. Known-sensitive fields (your card content, notes, uploaded text, tokens) are redacted before transmission.
2.4 When you upload content for AI card generation
- The content of your upload (slides, documents, text) is sent to Anthropic (our AI sub-processor) for the sole purpose of generating flashcards. Anthropic does not use API inputs to train their models by default, and we have not opted in to any training program. See Section 5 ("Sub-processors") for details.
2.5 What we do NOT collect
- Real names (unless you voluntarily include them in card content)
- Home or mailing addresses
- Date of birth
- Government identifiers
- Payment information (we do not yet offer paid tiers; when we do, payment info will be collected and processed by a third-party payment processor, not stored by us)
- Health or medical records
- Precise location data (coarse IP-based geolocation only)
- Contacts, calendars, or other device-level data
- Biometric data
2.6 Data from third parties
We do not purchase data about you from any third party. The only data we hold about you is what you give us directly or what is generated by your use of the Service.
3. Why we use your personal data (legal basis)
Under GDPR, we must name a legal basis for each category of processing. For users outside the EU/UK, this still accurately describes why we process.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the Service (signing you in, storing your cards, computing review schedules) | Email, all content you create, study activity, scheduling state | Contractual necessity (Art. 6(1)(b)) |
| Generate flashcards from your uploads using AI | Content you explicitly upload for this purpose | Contractual necessity (Art. 6(1)(b)) |
| Keep the Service secure, prevent abuse, enforce rate limits | IP, user ID hash, request metadata | Legitimate interest (Art. 6(1)(f)) |
| Diagnose and fix bugs via error monitoring | Error context (PII-scrubbed) | Legitimate interest (Art. 6(1)(f)) |
| Calibrate scheduling quality using aggregate timing data | Timing telemetry | Legitimate interest (Art. 6(1)(f)) |
| Respond to your rights requests | Whatever you identify in the request | Legal obligation (Art. 6(1)(c)) |
| Notify you of material changes to this Policy or the Service | Email address | Legitimate interest (Art. 6(1)(f)) |
We do not rely on consent as a legal basis for any of the above, because none of it is optional for the Service to function. If we add optional features in the future (e.g., marketing emails, analytics), those will require separate, granular consent.
4. How long we keep your personal data
- Account data, content, and study history: retained until you delete your account OR until the account is inactive for 3 consecutive years, whichever is sooner. Inactive accounts will be notified by email 30 days before automatic deletion.
- Log data (IP, request metadata): retained by our hosting and database providers for approximately 30 days for operational purposes.
- Error reports: retained in Sentry for 90 days, then auto-deleted per Sentry's default retention.
- Backups: our database is backed up daily. Backups are retained for 7 days. If you delete your account, your data may persist in backups for up to 7 additional days before those backups roll off. We will not restore your data from backup for any other purpose after deletion.
- Legal-hold exceptions: if we receive a valid legal preservation request (e.g., a subpoena), we may retain specific data longer to comply. This is rare and narrow.
5. Who we share your data with (sub-processors)
We do not sell, rent, or share your data with advertisers, data brokers, or any third party for their own marketing purposes.
We use the following sub-processors to operate the Service. They access your data only as necessary to perform their specific function.
| Sub-processor | Role | Data they process | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | All user content, auth credentials, timing state | AWS us-west-2 (United States) |
| Vercel, Inc. | Hosting, CDN, build infrastructure | Log data, request routing, static assets | United States (global CDN edges) |
| Anthropic, PBC | AI card generation from uploaded content | Only content you explicitly send for AI processing | United States |
| Sentry (Functional Software, Inc.) | Error monitoring | Error context and stack traces (PII-scrubbed) | United States |
| GitHub, Inc. | Source-code hosting, CI | Not your personal data; your data never reaches GitHub | United States |
Each of these sub-processors is bound by their own published privacy policies and data-processing terms. We have reviewed those terms and have entered into Data Processing Addenda (DPAs) where required by law.
We will notify you via email (and update this policy) if we add or change a sub-processor that handles your personal data, at least 30 days in advance where practical.
6. International data transfers
Embercard is operated from the United States, and all of our sub-processors are US-based. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred to the United States when you use the Service.
The United States is not recognized by the European Commission as providing an "adequate" level of data protection equivalent to the EEA. To lawfully transfer your data, we rely on:
- Standard Contractual Clauses (SCCs) as published by the European Commission, incorporated in our contracts with each sub-processor
- The UK International Data Transfer Addendum for UK-origin data
- Supplementary technical and organizational measures (encryption in transit and at rest, role-based access, per-user row-level security)
You can request copies of the relevant SCCs by writing to privacy@[DOMAIN-TBD].
7. Your rights
Wherever you live, we offer the following rights over your data. Most are enforced by regional law (GDPR in the EU/UK, CCPA/CPRA in California, similar laws in many other US states). We extend them to all users regardless of location.
- Right to access — know what data we have about you. We will provide a copy in a structured, machine-readable format within 30 days.
- Right to rectification — correct inaccurate data. Most corrections can be made by editing your content directly in the app; contact us for anything else.
- Right to erasure ("right to be forgotten") — delete your account and all associated data. See Section 8.
- Right to data portability — export your data as JSON in a downloadable archive. See Section 8.
- Right to object — object to processing based on our legitimate interests. We will stop the processing unless we demonstrate a compelling overriding interest.
- Right to restrict processing — pause our use of your data while we investigate a dispute.
- Right to withdraw consent — if processing is ever based on your consent, you can withdraw it at any time.
- Right to lodge a complaint — if you believe we've violated your rights, you can complain to your local data protection authority. EU users: find yours at edpb.europa.eu. UK users: ico.org.uk. California users: the California Privacy Protection Agency at cppa.ca.gov.
- Right against discrimination for exercising rights — we will not degrade service, raise prices, or deny access because you exercised your rights.
7.1 How to exercise your rights
Email privacy@[DOMAIN-TBD] from the email address associated with your Embercard account. We will respond within 30 days (or sooner where legally required). We may need to verify your identity before acting on your request.
You can also:
- Delete your account directly from Settings → Account → Delete Account (in-app)
- Export your data directly from Settings → Account → Export My Data (in-app, returns a ZIP of your data as JSON)
Self-service is always available. You do not need to email us to delete or export.
8. Account deletion and data export (in detail)
8.1 Deletion
When you delete your account:
- We cascade-delete all data we hold about you across every table in our database (your classes, decks, cards, study history, scheduling state, timing data, availability blocks, preferences)
- We delete all files you uploaded (stored images for Hide & Reveal cards, uploaded PDFs / PPTX / DOCX)
- We delete your authentication record
- We log a minimal record of the deletion itself — timestamp and a hashed user ID — in order to defend against any future dispute about whether the deletion occurred. This log contains no content about you.
- Your data may persist in backups for up to 7 days before those backups roll off. We will not restore your data from those backups for any purpose after deletion.
Deletion is immediate, irreversible, and applies to all devices — any active session tokens on other browsers or devices are invalidated.
8.2 Export
When you export your data, we return a ZIP archive containing:
classes.json,decks.json,cards.json,sources.json, and related files — all your content, as JSONstudy-history.json— your review events with timestamps, ratings, and FSRS state snapshotspreferences.json— your study preferences and timing profileREADME.md— a plain-language description of each file
We do not include raw uploaded files (PDFs, images) in the export because you already have access to them in the app. We include signed URLs (valid for 7 days) in sources.json if you want to download the originals.
You can export as many times as you like, subject to rate-limit protections against abuse.
9. Children's privacy
Embercard is not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13.
- At sign-up, we require you to confirm you are 13 years of age or older.
- Users aged 13 to 17 confirm they have parental or guardian permission to use the Service, and that their use is consistent with local law.
- If you are a parent or guardian and believe your child under 13 has provided us with personal data, email privacy@[DOMAIN-TBD] and we will delete the account and any associated data without unreasonable delay.
We comply with the US Children's Online Privacy Protection Act (COPPA) by maintaining a clearly-stated 13+ minimum age and by treating any account later discovered to belong to a child under 13 as a deletion request.
10. Cookies and tracking technologies
Embercard uses one category of cookies: essential session cookies.
Specifically, a single cookie named sb-<project-ref>-auth-token (set by Supabase) keeps you signed in as you navigate the Service. Without this cookie, the Service cannot function.
We do not use:
- Analytics cookies (Google Analytics, Mixpanel, Amplitude, etc.)
- Advertising cookies or tracking pixels
- Social media sharing widgets that set third-party cookies
- "Session replay" tools that record your clicks or typing
Because we only use strictly-necessary cookies, no cookie consent banner is required under GDPR / ePrivacy guidelines.
If we ever introduce analytics or other non-essential tracking, we will update this policy, and for EU/UK users we will present a consent banner before setting any non-essential cookie.
11. How we protect your data
- Encryption in transit: all communication with Embercard and its sub-processors is over TLS 1.2 or higher.
- Encryption at rest: our databases and file storage encrypt data at rest using AES-256 (provided by Supabase / AWS).
- Row-level security: every table in our database enforces per-user access controls at the database layer, meaning one user cannot read or modify another user's data even if a bug in our application code attempted it.
- Signed URLs for file access: files you upload (images, PDFs) are never publicly accessible. Access requires short-lived (≤ 5 minute) signed URLs generated on demand.
- Rate limiting: we limit how often certain actions can be performed per user to protect against abuse and runaway costs.
- Auth middleware: every request to a non-public URL is checked for a valid session before reaching application code.
- Error monitoring with PII scrubbing: Sentry receives stack traces but not your content; known sensitive fields are redacted before transmission.
- Multi-factor authentication on operator accounts: accounts with administrative access to the Service have MFA required.
No system is perfect. These measures are industry-standard but they do not guarantee absolute security. In the event of a breach, Section 12 applies.
12. Data breach notification
If we experience a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authorities within 72 hours of becoming aware of the breach, where required by applicable law
- Notify affected users without undue delay (via the email on your account) where the breach is likely to result in a high risk to your rights
- Publish a description of the incident, the scope, the mitigations, and your options on the Embercard status page
We commit to this 72-hour timeline for all users, regardless of whether local law requires it.
13. Automated decision-making
Embercard uses two types of automated processing:
- FSRS (spaced-repetition scheduling): decides when to show you each card next. This is a study-efficiency heuristic with no legal or similarly significant effect on you.
- AI card generation: when you upload study material, Anthropic's Claude model produces candidate flashcards. You review and accept/reject each card before it is saved. This is assistive, not automated decision-making in the GDPR Art. 22 sense.
Neither of these processes produces legal effects concerning you or similarly significantly affects you. You therefore do not have a right to object to them under GDPR Art. 22(1), but you can still choose not to use AI card generation by creating cards manually.
14. Your rights as a California resident (CCPA / CPRA)
California residents have specific rights under the California Consumer Privacy Act and California Privacy Rights Act. In addition to the rights in Section 7:
- Right to know categories of personal information collected, sources, purposes, and third parties we share with — covered above in Sections 2, 5, and 6.
- Right to know specific pieces of personal information we have collected — exercise via the export tool or by emailing privacy@[DOMAIN-TBD].
- Right to delete — via the in-app tool or by emailing us.
- Right to correct — via the in-app editor or by emailing us.
- Right to opt out of sale or sharing of personal information — we do not sell or share personal information as those terms are defined under CCPA. This right is therefore not applicable, but it remains available in principle.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined by CPRA (e.g., government ID, precise geolocation, biometrics, race, religion, etc.).
- Right against discrimination — we will not deny you service, charge different prices, or provide a different quality of service because you exercised your rights.
California residents can authorize an agent to exercise these rights on their behalf. We will require verification of the agent's authority before acting.
"Shine the Light" (Cal. Civ. Code §1798.83)
We do not share personal information with third parties for their own direct marketing purposes.
Notice of Financial Incentive
We do not offer financial incentives in exchange for personal data.
15. Your rights in the EU, UK, and EEA (GDPR / UK-GDPR)
All rights in Section 7 above are legally enforceable for users located in the EU, UK, or EEA.
Our data controller for GDPR purposes is Isabella Aguayo, operating as Embercard, reachable at privacy@[DOMAIN-TBD].
We do not have an EU representative under GDPR Art. 27 because we do not meet the thresholds (our processing is occasional, does not include special categories of data on a large scale, and does not pose a risk to rights and freedoms). We will appoint an EU representative if our processing changes in a way that triggers Art. 27.
Supervisory authority: if you are in the EU or UK, you can lodge a complaint with your national data protection authority. We will not retaliate or change our relationship with you in any way because you exercised this right.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes (changes that affect your rights or how we use your data) will be communicated via email to the address on your account at least 30 days before taking effect, unless a shorter period is required by law. Non-material changes (typos, clarifications, adding a sub-processor that does not change what data is processed) will be published with an updated "Effective Date" at the top.
We maintain an archive of prior versions and will make them available on request.
Your continued use of the Service after a new version takes effect constitutes acceptance. If you do not agree with a change, you can delete your account at any time (Section 8).
17. How to contact us
- For privacy questions or rights requests: privacy@[DOMAIN-TBD]
- For general support: [SUPPORT EMAIL OR SAME AS PRIVACY]
- By post: [PHYSICAL ADDRESS IF APPLICABLE — many sole proprietors list a PO Box to avoid listing a home address publicly. Recommended.]
We respond to all rights requests within 30 days. We respond to general support inquiries on a best-effort basis.
18. Effective date and version
- Version: 1.0
- Effective date: 2026-05-01
- Last updated: 2026-05-01
A cryptographic hash of this document at the time of your account creation is logged in your profile as proof of the exact version you accepted. This record is retained for the life of your account plus a minimum of 2 years after deletion, in order to defend against future disputes about what terms were in force when you used the Service.